A vulnerability identified as critical has been detected in Legion of the Bouncy Castle Bouncy Castle for Java, Bouncy Castle for Java LTS and Bouncy Castle for Java FIPS. Affected by this issue is some unknown functionality of the component AuthEnvelopedData. Performing a manipulation results in improper verification of cryptographic signature.

This vulnerability is known as CVE-2026-12802. Remote exploitation of the attack is possible. No exploit is available.